PT-2024-23087 · Misp · Misp

·

CVE-2024-29859

·

Published

2024-03-21

·

Updated

2024-08-05

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions MISP versions prior to 2.4.187
Description The issue arises from the add misp export function in app/Controller/EventsController.php not properly checking for a valid file upload. This could potentially lead to security weaknesses.
Recommendations For versions prior to 2.4.187, update to version 2.4.187 or later to resolve the issue. As a temporary workaround, consider restricting file upload capabilities until the update can be applied.

Exploit

Fix

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-29859

Affected Products

Misp